--- title: "Run email on your own EmailEngine server" description: "Move your workspace's mail onto an EmailEngine server you run: the token, the address we call from, webhooks, the checks and what we store." last_updated: "2026-09-27T02:01:34+03:00" --- # Run email on your own EmailEngine server Source: https://busymate.ai/docs/guides/email-emailengine Last modified: 2026-09-27T02:01:34+03:00 Busymate AI can run your workspace's email on an EmailEngine server you operate, so the mailboxes, their sign-ins and the mail stay on infrastructure you control. EmailEngine holds each mailbox connection, picks up new mail and sends replies. Ours is the default; on every plan you can move to your own, and the [email channel guide](https://busymate.ai/docs/guides/email) works the same on either. The settings sit under Console › Connections › **EmailEngine**: the **Overview**; **Server**, **Mailboxes**, **Folders** and **Import existing mail**; the rules pages **Inbound**, **Routing**, **AI replies**, **Outbound and identity**, **Threading** and **Notifications**; and **Data**, **Activity** and **Danger zone**. If **Server** is missing, EmailEngine is not switched on for your workspace yet. ## 1. What to run - [EmailEngine](https://learn.emailengine.app/docs) **2.72 or newer** (2.79.4 or newer recommended) with its Redis database, behind a reverse proxy that terminates TLS. - A public `https://` address on port 443 or 8443, with no user name or password in it, resolving only to public IP addresses and answering without redirects. - A clock within five minutes of ours, or its signed webhooks cannot be trusted. - Outbound HTTPS, so its webhooks reach us. - Its **Service URL** (Configuration → General) set to that address. OAuth2 mailboxes need an OAuth2 app registered on your EmailEngine; IMAP mailboxes need nothing extra. ## 2. The token to give us In EmailEngine, open **Integrations → Access Tokens** and create a token with: - **API access only** (the `api` scope), never full access (`*`). - **No account binding**: the connector creates mailboxes and reads server settings, so a token bound to one mailbox is refused. - **No section limits** (EmailEngine 2.80.1 and newer can set them); a limited token is refused. - **An address lock** (`restrictions.addresses`), if offered: list exactly the addresses in step 3. The token is kept in our credential store, never shown or logged. Replace it before any expiry under **Replace a secret** → **Access token**. ## 3. Where we call your server from Every call to your server comes from **142.93.32.78**. Allow that address, and nothing else of ours, on your firewall, your reverse proxy and the token's address lock. The Overview and the Server page show the current list under **Where we call your server from**, and it wins if it ever differs from this page; if it says no addresses are stated, contact us before narrowing access. With an IPv4-only list, publish only an A record for your EmailEngine host. ## 4. Your licence Your server needs your own [EmailEngine licence](https://learn.emailengine.app/docs/licensing), because EmailEngine's terms do not let a licence key be shared across organisations. Without one it stops syncing, sending and delivering webhooks. The **Licence** card on the Server page warns in the month, the week and on the day it ends, and shows **Unknown** when it cannot read the state. If it lapses, your mail stops, and we never route it through ours instead. ## 5. Webhooks Connecting adds any of these that are missing to your server's webhook event list (`webhookEvents`) and reads it back to prove it: `messageNew`, `messageSent`, `messageDeliveryError`, `messageFailed`, `messageBounce`, `messageComplaint`, `messageUpdated`, `messageDeleted`, `messageMissing`, `authenticationError`, `connectError`, `accountAdded`, `accountInitialized` and `accountDeleted`. It also turns on message text in webhooks and the headers our mail-loop protection reads (`Auto-Submitted`, `Precedence`, `List-Id` and a few more). EmailEngine signs every webhook with its service secret (`serviceSecret`) and never reveals the one it generated. Set your own with `serviceSecret` in `POST /v1/settings`, then paste it under **Replace a secret** → **Webhook signing secret**. Until then every webhook from your server is refused; a later replacement keeps the old secret working for ten minutes. ## 6. Connect it 1. On **Server**, under **Where your mail runs**, choose **Your own server**, with your mailboxes paused. 2. Enter the **Server address**, then paste the **Access token**. Eight checks run in order (the address, a public host, an answer, the version, what the server can do, its clock, the token, its licence) and **What we checked** shows each. A refusal stores nothing and names the fix; a check we could not complete never counts as a pass. **Check again** runs them anew. 3. Store the signing secret (step 5). 4. On **Mailboxes**, adopt the addresses already on your server or add one through its sign-in form. Adopting sets that address's own webhook to our address, instead of your server's default webhook, and reads **Delivery to us: registered**. A failure is listed on the Server page under **Mail that does not reach your mate** until **Re-check** gets through. An address whose own webhook already points somewhere else is not adopted. Then switch on **Let your mate use this mailbox**. 5. On **Folders**, choose what is watched for each mailbox. Earlier mailboxes stay on our server until you adopt or add them; **Moving your live mail across** on the Server page shows each step and the way back. A health check runs every five minutes, and three failures in a row mark the connection broken. ## What we store, and for how long Mailboxes, sign-ins and mail stay on your server. We hold your server's address, its token and signing secret, its health history (thirty days on **Activity**), and a copy of each message in a watched folder or sent through us: its text, its details, its webhook events and links to its attachments, which stream from your server. That copy is **kept forever by default**. On **Data** you set a number of days for each of those four parts, and a daily job removes what is older. The same page redacts card, bank and national ID numbers or your own patterns before storage, exports your mail, and removes test traffic or one mailbox's or one person's mail. ## Detaching **Danger zone** holds four actions, each naming what it touches first: - **Disconnect every mailbox**: mail stops arriving; the server and the history stay. - **Detach the server, keep the mail**: deletes our credentials for your server; the copied mail stays. Refused while a mailbox is connected. - **Forget the server and everything from it**: deletes everything copied from your server, checks it is gone, then detaches. There is no undo. - **Revoke our token**: your server stops accepting our token, and we check that it does. An account adopted from your server is never deleted there unless you switch on **Also delete the accounts we adopted on your server**. To return, pause your mailboxes, choose **Our shared server** and add them again. ## Verify 1. On **Server**, choose **Check again**: every check reads **Passed** or **Warning**, and **Health** shows a recent check. 2. Email a mailbox on your server from an account you do not otherwise use: the reply is marked **Sent** and arrives threaded. ### Do I need my own EmailEngine? No. Ours is the default and needs nothing from you. ### What happens if my server is down? Mail waits on your server until it answers again. It is never routed through our server in the meantime. ### Can I move back to your server? Yes. Pause your mailboxes, choose **Our shared server**, and add them again. Your token and signing secret are then deleted on our side.